SPRS Score Calculator for Small Business DoD Contractors
Self-score CMMC / NIST SP 800-171 without a consultant for every step — built for small DoD contractors.
Small defense contractors carry the same NIST SP 800-171 obligations as the primes — the requirements don't scale down with headcount. If you handle CUI, you need a current, defensible SPRS score to stay eligible for award, whether you're 5 people or 500.
What's different is leverage: leaner teams, tighter budgets, no dedicated compliance staff. The good news is that scope, not size, drives the work — a small shop that handles CUI on a handful of systems has a much smaller assessment than its system count suggests, once assets are categorized under 32 CFR 170.19.
The pragmatic path: determine your level, scope tightly to the systems that actually hold CUI, self-assess at the objective level to find your real gaps, then bring in outside help only where remediation genuinely needs it — rather than paying a consultant for every step.
What's typically in scope for Small Business Contractors
How the five CMMC asset categories (32 CFR 170.19) usually map to your environment — scope drives which requirements apply, so categorize before you assess.
| Asset | Category | What it means |
|---|---|---|
| The handful of systems (laptops, file storage, email) where CUI lives | CUI | In scope as CUI Assets — keep this set as small as you can. |
| A managed IT/security provider you rely on | Security Protection | An ESP / Security Protection Asset — assessed against its capability; document it in the SSP + CRM. |
| Productivity cloud (email/file) that stores CUI | CUI | If it holds CUI it's in scope; a CUI-handling cloud must meet FedRAMP Moderate or equivalency. |
| Personal/BYOD or general office systems kept clear of CUI | Out-of-Scope | Out of scope if genuinely separated and CUI never lands there — be ready to justify it. |
Where Small Business Contractors teams usually focus
Common areas to shore up — your real gaps come from the assessment, not a generic list.
- Tight scoping so a small system count stays a small assessment
- MFA and access control (often the highest-impact early wins)
- FIPS-validated encryption on the systems that hold CUI
- A real System Security Plan — its absence blocks a complete assessment
- A POA&M with owners and dates for the gaps you can't close yet
Which CMMC level you need
FCI-only work is Level 1 (15 FAR 52.204-21 safeguards). Any CUI raises the floor to Level 2 (the 110 requirements). The level-determination wizard helps you confirm which applies before you start.
Run the level-determination wizardWhat you need to know
- Your SPRS score starts at a baseline of 110 and subtracts a weighted value (5, 3, or 1) for each unimplemented requirement — it can go negative (as low as −203).
- A score of 110 is a Final self-assessment; 88–109 is Conditional with a POA&M; below 88 you can't affirm a Conditional or Final status.
- A Conditional Level 2 self-assessment is valid 180 days to close your POA&M; a Final self-assessment is valid 3 years with annual affirmations.
Clauses that likely apply to you

Know your score before you submit
Run a full 110-requirement self-assessment free — no account required to see your score.
Start free assessmentFree tools
Frequently asked questions
- Do small businesses really have to do this?
- Yes. NIST SP 800-171 obligations do not scale down with company size. If you handle CUI, you need a current SPRS score regardless of headcount.
- Do I need a consultant?
- Not necessarily for the self-assessment. A guided, objective-level tool lets many small contractors self-assess; you can bring in help for remediation where it is needed.
- How much does compliance cost?
- It varies with your gaps. The assessment itself is free here — the real cost is remediating not-met requirements, so start by scoring to see where you stand.
- Where should a small contractor start?
- Run the level-determination wizard, then scope to the systems that actually handle CUI — that single step often shrinks the work more than anything else. Then self-assess at the objective level to see your true gaps.
- Is a System Security Plan really required for a small business?
- Yes. The SSP (3.12.4) is a prerequisite, not a scored line item — without it an assessment can't be completed (and it signals noncompliance with DFARS 252.204-7012). Even a lean, accurate SSP satisfies it.
Related industries
Related guides
Go deeper on scoring, levels, and POA&Ms.